Policy Exceptions
Exceptions allow users to bypass specific policies when there's a legitimate business need. This guide covers how to create, manage, and audit exceptions.
When to Use Exceptions
Exceptions are appropriate when:
- A user needs to discuss sensitive data for legitimate business
- Test data triggers policies (e.g., test credit cards)
- Security team needs unrestricted access for investigation
- Temporary project requires different rules
Exceptions are not appropriate for:
- Avoiding policies you disagree with
- Permanent workarounds (adjust the policy instead)
- Bypassing compliance requirements
Exception Types
User Exceptions
Grant an individual user the ability to bypass a policy.
Example: Security analyst investigating a breach needs to share sample data with AI for analysis.
Team Exceptions
Allow all members of a team to bypass a policy.
Example: Security team needs unrestricted access during incident response.
Policy Exceptions
Create an allowlist for specific content patterns.
Example: Test credit card numbers should never trigger alerts.
Temporary Exceptions
Time-limited exceptions that automatically expire.
Example: Contractor needs access for a 2-week project.
Creating Exceptions
From an Alert
- Open the alert that was incorrectly triggered
- Click Grant Exception
- Configure:
- Type: User, Pattern, or Both
- Duration: Permanent or time-limited
- Scope: This policy or all policies
- Add justification (required)
- Click Create Exception
From Policy Settings
- Open the policy configuration
- Click Exceptions tab
- Click Add Exception
- Configure the exception details
- Save
From Exception Management
- Go to Settings > Exceptions
- Click Create Exception
- Select policy
- Configure details
- Save
Exception Configuration
User-Based Exception
Type: User
User: analyst@company.com
Policy: SSN Detection
Duration: 30 days
Justification: "Authorized for breach investigation - Ticket #5678"
Approved By: admin@company.com
Pattern-Based Exception
Type: Pattern
Pattern: "4111111111111111"
Policy: Credit Card Detection
Duration: Permanent
Justification: "Test credit card number for development"
Approved By: admin@company.com
Team Exception
Type: Team
Team: Security Operations
Policy: All Credential Policies
Duration: Permanent
Justification: "SOC requires unrestricted AI access for investigations"
Approved By: ciso@company.com
Exception Fields
| Field | Description | Required |
|---|---|---|
| Type | User, Team, or Pattern | Yes |
| Subject | Who/what the exception applies to | Yes |
| Policy | Which policy to bypass | Yes |
| Duration | How long the exception lasts | Yes |
| Justification | Business reason | Yes |
| Ticket Reference | Related ticket/request | Recommended |
| Approved By | Who approved | Auto-filled |
Managing Exceptions
Viewing Exceptions
Go to Settings > Exceptions to see:
- All active exceptions
- Expired exceptions
- Pending approvals
Filtering Exceptions
Filter by:
- Status (Active, Expired, Pending)
- Type (User, Team, Pattern)
- Policy
- Created date
- Expiration date
Modifying Exceptions
- Find the exception in the list
- Click to open details
- Click Edit
- Make changes
- Add note explaining the change
- Save
Revoking Exceptions
- Find the exception
- Click Revoke
- Add reason for revocation
- Confirm
Revoked exceptions take effect immediately.
Approval Workflow
EnterpriseConfiguring Approval
- Go to Settings > Permissions
- Configure Exception Approval:
- Who can create exceptions
- Who can approve exceptions
- Approval requirements by policy severity
Approval Flow
- User requests exception
- Request goes to approver queue
- Approver reviews and approves/denies
- User notified of decision
- If approved, exception activates
Multi-Level Approval
For high-risk policies, require multiple approvers:
- First approval from team lead
- Second approval from security admin
Exception Audit
All exceptions are logged for compliance:
Audit Trail
Each exception records:
- When created
- Who created
- Who approved
- All modifications
- When expired/revoked
Exception Reports
Generate reports showing:
- Active exceptions by policy
- Exception request volume
- Approval rates
- Average duration
Compliance Review
Regularly review exceptions:
- Monthly review of all active exceptions
- Quarterly justification verification
- Annual exception policy review
Best Practices
Justification
- Be specific about the business need
- Reference related tickets
- Include expected end date
Duration
- Prefer time-limited exceptions
- Set realistic durations
- Review before renewal
Scope
- Keep scope as narrow as possible
- Single policy over "all policies"
- Single user over team when possible
Documentation
- Maintain exception request records
- Document approval reasoning
- Track exception usage
Troubleshooting
Exception Not Working
- Verify exception is active (not pending)
- Check scope matches the situation
- Confirm user is covered
- Review policy hasn't changed
Expired Unexpectedly
- Check configured duration
- Look for revocation in history
- Verify no conflicting policy changes
Can't Create Exception
- Check your permissions
- Verify you have exception creation rights
- Contact admin if needed
Related Topics
- Policy Overview - How policies work
- Configuring Policies - Adjust policies instead of exceptions
- Permissions - Who can create exceptions